Dutch police disrupts botnet composed of 17 million devices

2026-05-29T20:51:48Z54016ab79ea4c6fb8c9f5cc51ae23c79d18262217e62e575d72659c3f64bb642
Adobe A/B testingAnthropic ClaudeCPS securityCVE-2026-35616Claroty ClaireDutch policeFROSTFortiClient EMSHumanixLinkedIn-themed phishingMicrosoft 365 CopilotNetskope NewEdgeOPFSSSD fingerprintingbehavioral analysisbotnetdata localizationfingerprintinginfostealerinsider threat detectionphishingprivacysecurity-researchtrojan detection

What happened

A batch of security news: Dutch authorities disrupted 200 servers controlling a botnet infecting an estimated 17 million devices. Attackers are actively exploiting a FortiClient EMS improper access control vulnerability (CVE-2026-35616) to deliver a broad-spectrum infostealer via forged Fortinet endpoint updates and FortiClient-managed VPN scripting workflows. Researchers demonstrated FROST, an OPFS-based SSD timing technique that lets websites infer user activity from SSD behavior, creating a new privacy/fingerprinting vector. A LinkedIn-themed phishing campaign is abusing Adobe’s A/B testing

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
54016ab79ea4c6fb8c9f5cc51ae23c79d18262217e62e575d72659c3f64bb642
Enrichment time
2026-05-29T20:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.